Brief IA

CrowdStrike: AI as a Weapon and Target of Cyberattacks

🛠️ AI Tools·Tom Levy·

CrowdStrike: AI as a Weapon and Target of Cyberattacks

CrowdStrike: AI as a Weapon and Target of Cyberattacks
Key Takeaways
1The 2026 report from CrowdStrike reveals that AI is being used by cybercriminals to increase attacks on businesses.
2Groups like Famous Chollima are exploiting AI to infiltrate the cryptocurrency and blockchain sectors.
3Vulnerabilities are being exploited in less than 48 hours, highlighting the urgency for businesses to strengthen their cybersecurity.
💡Why it mattersAI accelerates cyber threats, forcing businesses to adopt more proactive and robust defense strategies.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

AI: A Double-Edged Sword for Cybersecurity

Artificial intelligence (AI) is now seen as a dual-use tool in the field of cybersecurity: it is both a powerful weapon for cybercriminals and a prime target for their attacks. This duality forces companies to rethink their defense strategies to face increasingly sophisticated and difficult-to-manage threats.

According to the recent 2026 Threat Hunting Report from CrowdStrike, published this Monday, the same AI technologies that promise to enhance business productivity are also being exploited by cybercriminals on a large scale. These criminals use these tools to conduct more effective and faster attacks.

With the continued expansion of enterprise networks, the addition of endpoint devices, and the deployment of new large language models (LLMs), organizations are inadvertently creating larger attack surfaces. These surfaces can be exploited to steal data, access AI models, conduct surveillance operations, and even hijack computing resources for malicious purposes.

AI: A Weapon and a Target

Adam Meyers, head of threat intelligence at CrowdStrike, emphasizes that AI is not just a tool or a weapon, but also an attack surface in itself. Malicious actors are adopting AI as quickly as businesses, complicating the task for defenders.

The report indicates that the massive adoption of AI, often new and untested, significantly increases the volume of signals that security teams must analyze. There are now 2.5 times more trails generated by AI agents than by manual methods, making it harder to distinguish between malicious activity and normal AI-driven behavior.

Alerts and suspicious signals highlight the use of AI in the criminal world, where attacks are carried out at an impressive speed. CrowdStrike cites several examples:

  • Famous Chollima: This group, linked to North Korea, uses trusted AI environments and tools to target cryptocurrency and blockchain companies, employing AI-generated resumes and deepfake interviews.

  • Cordial Spider and Snarky Spider: These groups use vishing to extract data from SaaS applications and compromise single sign-on accounts. A documented attack transitioned from account takeover to data theft in less than five minutes.

  • LLMJacking: This term refers to unauthorized access to keys or credentials that allow access to a company's AI models. Cybercriminals can then steal data or force the model to execute costly tasks, leading to high bills for the victim. For instance, one campaign used the victim's LLM to generate nearly 200,000 API requests in two minutes, causing significant financial and operational impact.

Reducing Vulnerability Windows

The report also highlights a concerning trend: the shrinking time defenders have to react between the discovery of a vulnerability and its exploitation. From January to June 2026, 88% of exploits detected by CrowdStrike were launched within 48 hours of the publication of a proof-of-concept (PoC) code.

Certain threat groups, such as Vault Panda and Genesis Panda from China, closely monitor new vulnerabilities. They developed functional exploits for a critical vulnerability in a web application (React2Shell) in just 24 hours after its disclosure.

In these cases, AI plays a crucial role. Two recently discovered exploits, CopyFail and Fragnesia (with Dirty Frag as a third), were identified through AI-assisted research. The report notes that cybercriminals quickly integrated them into their operations.

Implications for Businesses and Their Cybersecurity Teams

CrowdStrike warns that response times will continue to shorten, largely due to the weaponization of AI. Researchers believe that the implementation of advanced AI systems could accelerate the discovery of vulnerabilities and the development of exploits, thereby increasing pressure on already overwhelmed defenders.

Recommended Actions

While AI can act as a shield, it can also be used as a weapon, as shown by CrowdStrike's research. In the face of growing pressure from AI, defenders must double their efforts to secure networks and endpoints.

CrowdStrike recommends that companies adopt the following practices:

  • Secure AI Applications and LLMs: With AI integrated into many enterprise environments, it is crucial to apply least privilege principles, protect AI-related credentials, and monitor for suspicious LLM usage or cost spikes to mitigate risks.

  • Identity as the Primary Attack Surface: Although this issue predates AI, securing and verifying identities is now more important than ever. Organizations must implement phishing-resistant multifactor authentication, monitor access to enterprise resources, and apply least privilege to both human and non-human accounts.

  • Address Cross-Domain Blind Spots and Secure the Software Supply Chain: Digital blind spots in the supply chain and within networks can be exploited. Telemetry, behavioral detection, and analytics software, along with frequent patch cycles and threat intelligence, can reduce the risk of compromise.

  • Adopt a Proactive Approach: The weaponization of AI, moving at a speed we cannot keep up with, forces organizations to shift from a reactive security posture to a proactive one. Investment, threat triage, and resolution of legacy security issues must be addressed swiftly to reduce the attack surface and give teams the space needed to keep pace.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.